<!DOCTYPE html>
<html lang="en">

<head>
    <meta charset="UTF-8">
    <meta http-equiv="X-UA-Compatible" content="IE=edge">
    <meta name="viewport" content="width=device-width, initial-scale=1.0">
    <link href="https://cdn.jsdelivr.net/npm/bootstrap@5.3.0-alpha1/dist/css/bootstrap.min.css" rel="stylesheet"
        integrity="sha384-GLhlTQ8iRABdZLl6O3oVMWSktQOp6b7In1Zl3/Jr59b6EGGoI1aFkw7cmDA6j6gD" crossorigin="anonymous">
    <link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.3.0/css/all.min.css"
        integrity="sha512-SzlrxWUlpfuzQ+pcUCosxcglQRNAq/DZjVsC0lE40xsADsfeQoEypE+enwcOiGjk/bSuGGKHEyjSoQ1zVisanQ=="
        crossorigin="anonymous" referrerpolicy="no-referrer" />
</head>
</html>
3
lá˜_Ì6  ã               @   sô   d dl mZmZmZ d dlZd dlmZmZ d dlm	Z	 d dl
mZmZmZmZmZmZ d dlmZ d dlmZ d dlmZmZmZmZmZmZmZ d	d
„ Zdd„ Zdd„ Zdd„ Z dd„ Z!ej"eƒG dd„ de#ƒƒZ$ej"eƒG dd„ de#ƒƒZ%dS )é    )Úabsolute_importÚdivisionÚprint_functionN)ÚutilsÚx509)ÚUnsupportedAlgorithm)Ú_CRL_ENTRY_REASON_CODE_TO_ENUMÚ_asn1_integer_to_intÚ_asn1_string_to_bytesÚ_decode_x509_nameÚ_obj2txtÚ_parse_asn1_generalized_time)Ú_Certificate)Úserialization)ÚOCSPCertStatusÚOCSPRequestÚOCSPResponseÚOCSPResponseStatusÚ_CERT_STATUS_TO_ENUMÚ_OIDS_TO_HASHÚ_RESPONSE_STATUS_TO_ENUMc                s   t jˆ ƒ‡ fdd„ƒ}|S )Nc                s(   | j tjkrtdƒ‚nˆ | f|žŽ S d S )NzCOCSP response status is not successful so the property has no value)Úresponse_statusr   Ú
SUCCESSFULÚ
ValueError)ÚselfÚargs)Úfunc© ú/usr/lib64/python3.6/ocsp.pyÚwrapper!   s    z._requires_successful_response.<locals>.wrapper)Ú	functoolsÚwraps)r   r   r   )r   r   Ú_requires_successful_response    s    
r"   c             C   s^   | j jdƒ}| jj| j j| j j|| j j|ƒ}| j|dkƒ | j|d | j jkƒ t| |d ƒS )NzASN1_OCTET_STRING **é   r   )Ú_ffiÚnewÚ_libÚOCSP_id_get0_infoÚNULLÚopenssl_assertr
   )ÚbackendÚcert_idZkey_hashÚresr   r   r   Ú_issuer_key_hash.   s    r-   c             C   s^   | j jdƒ}| jj|| j j| j j| j j|ƒ}| j|dkƒ | j|d | j jkƒ t| |d ƒS )NzASN1_OCTET_STRING **r#   r   )r$   r%   r&   r'   r(   r)   r
   )r*   r+   Z	name_hashr,   r   r   r   Ú_issuer_name_hash<   s    r.   c             C   s^   | j jdƒ}| jj| j j| j j| j j||ƒ}| j|dkƒ | j|d | j jkƒ t| |d ƒS )NzASN1_INTEGER **r#   r   )r$   r%   r&   r'   r(   r)   r	   )r*   r+   Únumr,   r   r   r   Ú_serial_numberJ   s    r0   c             C   sŽ   | j jdƒ}| jj| j j|| j j| j j|ƒ}| j|dkƒ | j|d | j jkƒ t| |d ƒ}yt| S  tk
rˆ   t	dj
|ƒƒ‚Y nX d S )NzASN1_OBJECT **r#   r   z*Signature algorithm OID: {} not recognized)r$   r%   r&   r'   r(   r)   r   r   ÚKeyErrorr   Úformat)r*   r+   Zasn1objr,   Úoidr   r   r   Ú_hash_algorithmT   s    r4   c               @   sb  e Zd Zdd„ ZejdƒZeedd„ ƒƒZ	eedd„ ƒƒZ
eedd	„ ƒƒZeed
d„ ƒƒZeedd„ ƒƒZeedd„ ƒƒZeedd„ ƒƒZdd„ Zeedd„ ƒƒZeedd„ ƒƒZeedd„ ƒƒZeedd„ ƒƒZeedd„ ƒƒZeedd„ ƒƒZeed d!„ ƒƒZeed"d#„ ƒƒZeed$d%„ ƒƒZeed&d'„ ƒƒZejed(d)„ ƒƒZejed*d+„ ƒƒZd,d-„ Zd.S )/Ú_OCSPResponsec             C   s   || _ || _| j jj| jƒ}| j j|tkƒ t| | _| jtjkrü| j jj	| jƒ}| j j|| j j
jkƒ | j j
j|| j jjƒ| _| j jj| jƒ}|dkr¦tdj|ƒƒ‚| j jj| jdƒ| _| j j| j| j j
jkƒ | j jj| jƒ| _| j j| j| j j
jkƒ d S )Nr#   zhOCSP response contains more than one SINGLERESP structure, which this library does not support. {} foundr   )Ú_backendÚ_ocsp_responser&   ZOCSP_response_statusr)   r   Ú_statusr   r   ZOCSP_response_get1_basicr$   r(   ÚgcZOCSP_BASICRESP_freeÚ_basicZOCSP_resp_countr   r2   ZOCSP_resp_get0Ú_singleZOCSP_SINGLERESP_get0_idÚ_cert_id)r   r*   Zocsp_responseÚstatusZbasicZnum_respr   r   r   Ú__init__j   s.    

z_OCSPResponse.__init__r8   c             C   s>   | j jj| jƒ}| j j|| j jjkƒ t| j |jƒ}t	j
|ƒS )N)r6   r&   ZOCSP_resp_get0_tbs_sigalgr:   r)   r$   r(   r   Ú	algorithmr   ZObjectIdentifier)r   Zalgr3   r   r   r   Úsignature_algorithm_oidŒ   s    z%_OCSPResponse.signature_algorithm_oidc             C   s8   | j }y
tj| S  tk
r2   tdj|ƒƒ‚Y nX d S )Nz)Signature algorithm OID:{} not recognized)r@   r   Z_SIG_OIDS_TO_HASHr1   r   r2   )r   r3   r   r   r   Úsignature_hash_algorithm”   s    
z&_OCSPResponse.signature_hash_algorithmc             C   s2   | j jj| jƒ}| j j|| j jjkƒ t| j |ƒS )N)r6   r&   ZOCSP_resp_get0_signaturer:   r)   r$   r(   r
   )r   Zsigr   r   r   Ú	signatureŸ   s    z_OCSPResponse.signaturec                s¢   ˆ j jjˆ jƒ}ˆ j j|ˆ j jjkƒ ˆ j jjdƒ}ˆ j jj||ƒ}ˆ j j|d ˆ j jjkƒ ˆ j jj	|‡ fdd„ƒ}ˆ j j|dkƒ ˆ j jj
|d |ƒd d … S )Nzunsigned char **r   c                s   ˆ j jj| d ƒS )Nr   )r6   r&   ZOPENSSL_free)Zpointer)r   r   r   Ú<lambda>¯   s    z2_OCSPResponse.tbs_response_bytes.<locals>.<lambda>)r6   r&   ZOCSP_resp_get0_respdatar:   r)   r$   r(   r%   Zi2d_OCSP_RESPDATAr9   Úbuffer)r   ZrespdataZppr,   r   )r   r   Útbs_response_bytes¦   s    z _OCSPResponse.tbs_response_bytesc             C   sz   | j jj| jƒ}| j jj|ƒ}g }xRt|ƒD ]F}| j jj||ƒ}| j j|| j jj	kƒ t
| j |ƒ}| |_|j|ƒ q,W |S )N)r6   r&   ZOCSP_resp_get0_certsr:   Zsk_X509_numÚrangeZsk_X509_valuer)   r$   r(   r   Z
_ocsp_respÚappend)r   Zsk_x509r/   ZcertsÚir   Zcertr   r   r   Úcertificates´   s    z_OCSPResponse.certificatesc             C   s.   | j ƒ \}}|| jjjkrd S t| j|ƒS d S )N)Ú_responder_key_namer6   r$   r(   r
   )r   Ú_Úasn1_stringr   r   r   Úresponder_key_hashÆ   s    z _OCSPResponse.responder_key_hashc             C   s.   | j ƒ \}}|| jjjkrd S t| j|ƒS d S )N)rJ   r6   r$   r(   r   )r   Ú	x509_namerK   r   r   r   Úresponder_nameÏ   s    z_OCSPResponse.responder_namec             C   sP   | j jjdƒ}| j jjdƒ}| j jj| j||ƒ}| j j|dkƒ |d |d fS )NzASN1_OCTET_STRING **zX509_NAME **r#   r   )r6   r$   r%   r&   ZOCSP_resp_get0_idr:   r)   )r   rL   rN   r,   r   r   r   rJ   Ø   s    z!_OCSPResponse._responder_key_namec             C   s   | j jj| jƒ}t| j |ƒS )N)r6   r&   ZOCSP_resp_get0_produced_atr:   r   )r   Úproduced_atr   r   r   rP   á   s    z_OCSPResponse.produced_atc             C   sH   | j jj| j| j jj| j jj| j jj| j jjƒ}| j j|tkƒ t| S )N)r6   r&   ÚOCSP_single_get0_statusr;   r$   r(   r)   r   )r   r=   r   r   r   Úcertificate_statusé   s    z _OCSPResponse.certificate_statusc             C   sr   | j tjk	rd S | jjjdƒ}| jjj| j| jjj	|| jjj	| jjj	ƒ | jj
|d | jjj	kƒ t| j|d ƒS )NzASN1_GENERALIZEDTIME **r   )rR   r   ÚREVOKEDr6   r$   r%   r&   rQ   r;   r(   r)   r   )r   Ú	asn1_timer   r   r   Úrevocation_timeö   s    z_OCSPResponse.revocation_timec             C   s|   | j tjk	rd S | jjjdƒ}| jjj| j|| jjj	| jjj	| jjj	ƒ |d dkrXd S | jj
|d tkƒ t|d  S d S )Nzint *r   r#   éÿÿÿÿ)rR   r   rS   r6   r$   r%   r&   rQ   r;   r(   r)   r   )r   Z
reason_ptrr   r   r   Úrevocation_reason  s    z_OCSPResponse.revocation_reasonc             C   sb   | j jjdƒ}| j jj| j| j jj| j jj|| j jjƒ | j j|d | j jjkƒ t| j |d ƒS )NzASN1_GENERALIZEDTIME **r   )	r6   r$   r%   r&   rQ   r;   r(   r)   r   )r   rT   r   r   r   Úthis_update  s    z_OCSPResponse.this_updatec             C   sb   | j jjdƒ}| j jj| j| j jj| j jj| j jj|ƒ |d | j jjkrZt| j |d ƒS d S d S )NzASN1_GENERALIZEDTIME **r   )r6   r$   r%   r&   rQ   r;   r(   r   )r   rT   r   r   r   Únext_update,  s    z_OCSPResponse.next_updatec             C   s   t | j| jƒS )N)r-   r6   r<   )r   r   r   r   Úissuer_key_hash<  s    z_OCSPResponse.issuer_key_hashc             C   s   t | j| jƒS )N)r.   r6   r<   )r   r   r   r   Úissuer_name_hashA  s    z_OCSPResponse.issuer_name_hashc             C   s   t | j| jƒS )N)r4   r6   r<   )r   r   r   r   Úhash_algorithmF  s    z_OCSPResponse.hash_algorithmc             C   s   t | j| jƒS )N)r0   r6   r<   )r   r   r   r   Úserial_numberK  s    z_OCSPResponse.serial_numberc             C   s   | j jj| jƒS )N)r6   Z_ocsp_basicresp_ext_parserÚparser:   )r   r   r   r   Ú
extensionsP  s    z_OCSPResponse.extensionsc             C   s   | j jj| jƒS )N)r6   Z_ocsp_singleresp_ext_parserr^   r;   )r   r   r   r   Úsingle_extensionsU  s    z_OCSPResponse.single_extensionsc             C   sL   |t jjk	rtdƒ‚| jjƒ }| jjj|| jƒ}| jj	|dkƒ | jj
|ƒS )Nz/The only allowed encoding value is Encoding.DERr   )r   ÚEncodingÚDERr   r6   Ú_create_mem_bio_gcr&   Zi2d_OCSP_RESPONSE_bior7   r)   Ú_read_mem_bio)r   ÚencodingÚbior,   r   r   r   Úpublic_bytesZ  s    

z_OCSPResponse.public_bytesN)Ú__name__Ú
__module__Ú__qualname__r>   r   Zread_only_propertyr   Úpropertyr"   r@   rA   rB   rE   rI   rM   rO   rJ   rP   rR   rU   rW   rX   rY   rZ   r[   r\   r]   Úcached_propertyr_   r`   rg   r   r   r   r   r5   h   sT    

	r5   c               @   sZ   e Zd Zdd„ Zedd„ ƒZedd„ ƒZedd„ ƒZed	d
„ ƒZe	j
dd„ ƒZdd„ ZdS )Ú_OCSPRequestc             C   s~   |j j|ƒdkrtdƒ‚|| _|| _| jj j| jdƒ| _| jj| j| jjj	kƒ | jj j
| jƒ| _| jj| j| jjj	kƒ d S )Nr#   z+OCSP request contains more than one requestr   )r&   ZOCSP_request_onereq_countÚNotImplementedErrorr6   Ú_ocsp_requestZOCSP_request_onereq_get0Z_requestr)   r$   r(   ZOCSP_onereq_get0_idr<   )r   r*   Zocsp_requestr   r   r   r>   h  s    z_OCSPRequest.__init__c             C   s   t | j| jƒS )N)r-   r6   r<   )r   r   r   r   rZ   v  s    z_OCSPRequest.issuer_key_hashc             C   s   t | j| jƒS )N)r.   r6   r<   )r   r   r   r   r[   z  s    z_OCSPRequest.issuer_name_hashc             C   s   t | j| jƒS )N)r0   r6   r<   )r   r   r   r   r]   ~  s    z_OCSPRequest.serial_numberc             C   s   t | j| jƒS )N)r4   r6   r<   )r   r   r   r   r\   ‚  s    z_OCSPRequest.hash_algorithmc             C   s   | j jj| jƒS )N)r6   Z_ocsp_req_ext_parserr^   ro   )r   r   r   r   r_   †  s    z_OCSPRequest.extensionsc             C   sL   |t jjk	rtdƒ‚| jjƒ }| jjj|| jƒ}| jj	|dkƒ | jj
|ƒS )Nz/The only allowed encoding value is Encoding.DERr   )r   ra   rb   r   r6   rc   r&   Zi2d_OCSP_REQUEST_bioro   r)   rd   )r   re   rf   r,   r   r   r   rg   Š  s    
z_OCSPRequest.public_bytesN)rh   ri   rj   r>   rk   rZ   r[   r]   r\   r   rl   r_   rg   r   r   r   r   rm   f  s   rm   )&Z
__future__r   r   r   r    Zcryptographyr   r   Zcryptography.exceptionsr   Z0cryptography.hazmat.backends.openssl.decode_asn1r   r	   r
   r   r   r   Z)cryptography.hazmat.backends.openssl.x509r   Zcryptography.hazmat.primitivesr   Zcryptography.x509.ocspr   r   r   r   r   r   r   r"   r-   r.   r0   r4   Zregister_interfaceÚobjectr5   rm   r   r   r   r   Ú<module>   s"    $
 ~